Snowflake SnowPro Advanced: Security Engineer (SEA-C01) Lessons
21 lessons, one per exam-guide subdomain, in the order the guide teaches them. Every claim is cited to the official documentation.
Domain 1: Account and Security
4 lessons · 22% of the exam
1.1Snowflake RBAC: system roles, role types and least-privilege hierarchies
Subdomain 1.1: Design and implement access control strategies.
2 pages · 22 min read
1.2Snowflake MFA, Passkeys, SAML SSO and OAuth Sign-In
Subdomain 1.2: Configure and monitor user authentication and session management.
2 pages · 26 min read
1.3Snowflake Network Rules and Network Policies
Subdomain 1.3: Implement network security controls.
2 pages · 20 min read
1.4External Access Integrations: Egress Network Rules, Setup Order and Governance
Subdomain 1.4: Manage external access integrations.
2 pages · 20 min read
Domain 2: Data Protection, Data Privacy, and Data Governance
7 lessons · 30% of the exam
2.1Tri-Secret Secure CMKs and Dynamic Data Masking policies
Subdomain 2.1: Implement data security features.
3 pages · 26 min read
2.2Secure Objects, Listings and Reader Accounts in Snowflake Data Sharing
Subdomain 2.2: Manage and audit Secure Data Sharing and collaborations.
2 pages · 21 min read
2.3Restricting Unload Destinations with Account and User Parameters
Subdomain 2.3: Restrict data exfiltration.
2 pages · 17 min read
2.4Time Travel and Fail-safe: Retention Settings and Recovery Boundaries
Subdomain 2.4: Establish and manage data retention and data lifecycle management.
2 pages · 19 min read
2.5Snowflake Tag Inheritance, Propagation, Auditing and Lineage
Subdomain 2.5: Configure object tagging and data classification frameworks.
2 pages · 24 min read
2.6Replication Privileges, Group Ownership and Network Policy Replication
Subdomain 2.6: Configure and maintain data replication policies and procedures.
2 pages · 20 min read
2.7Snowflake Failover Readiness Audits and Client Redirect
Subdomain 2.7: Manage secure replication and failover operations.
2 pages · 18 min read
Domain 3: Auditing, Monitoring, and Compliance
3 lessons · 18% of the exam
3.1Audit data access with QUERY_HISTORY, ACCESS_HISTORY and LOGIN_HISTORY
Subdomain 3.1: Monitor data security.
2 pages · 20 min read
3.2Security Features and Their Credit Footprint in Snowflake
Subdomain 3.2: Implement a strategic security architecture to balance data protection and credit efficiency.
2 pages · 21 min read
3.3Snowflake Controls That Support GDPR, HIPAA, CCPA and PCI DSS
Subdomain 3.3: Design and manage data compliance policies.
2 pages · 17 min read
Domain 4: Threats, Risk Assessment, Incident Response, and Forensics
4 lessons · 18% of the exam
4.1Snowflake threat modeling: assets, entry points, exit points and shares
Subdomain 4.1: Perform threat modeling, identification, and analyses.
2 pages · 20 min read
4.2Snowflake Risk Assessment with Horizon Catalog and Trust Center
Subdomain 4.2: Perform risk assessment and manage risk.
2 pages · 19 min read
4.3Snowflake Incident Detection, Triage and Containment
Subdomain 4.3: Identify and manage security incidents.
2 pages · 19 min read
4.4Snowflake Forensic Evidence: Account Usage, Time Travel and Fail-safe
Subdomain 4.4: Conduct a post-security-incident forensic analysis.
2 pages · 20 min read
Domain 5: Securing Snowflake Services and Features for AI/ML and Applications
3 lessons · 12% of the exam
5.1Snowpark Container Services: Compute Pools, Privileges and Service Identity
Subdomain 5.1: Secure and govern applications with Snowpark Container Services.
2 pages · 19 min read
5.2Cortex LLM Content Safety: COMPLETE, TRY_COMPLETE, Cortex Guard and CLASSIFY_TEXT
Subdomain 5.2: Leverage Snowflake Cortex AI to enhance data security.
2 pages · 23 min read
5.3Native App Security Review, Code Requirements and Containers
Subdomain 5.3: Manage security in Snowflake Native Apps.
2 pages · 20 min read